Texas Cybersecurity Framework Assessment
Assess your Texas K-12 district, state agency, or nonprofit against all 42 TCF control objectives using DIR's official 0-5 maturity scale — aligned to the TEA K-12 Cybersecurity Initiative methodology.
Framework
Why This Matters
Texas K-12 Cybersecurity is Now a Funded Initiative
The TEA K-12 Cybersecurity Initiative funds EDR, MFA, DMARC, and TCF assessments through FY27. Districts that complete a structured TCF self-assessment know exactly which TEA-funded controls to prioritize.
FY26-FY27 TEA appropriations supporting K-12 cybersecurity, on top of $55M committed in FY24-FY25. Districts that align to TCF qualify for the most TEA-funded support.
Source: Texas Education Agency
One TCF assessment maps directly to NIST 800-53 Rev. 5, NIST CSF 2.0, and CIS Controls v8.1. A single engagement satisfies multiple framework expectations.
FrameworkMapper crosswalk dataset
Control objectives across 5 functions (Identify, Protect, Detect, Respond, Recover). Each scored on a 0-5 maturity scale derived from CMMI / ISO 21827.
Source: DIR TCF Controls and Definitions, May 2025
DIR's recommended target maturity for state agencies and the convention TEA aligns to for K-12. The assessment shows your gap from target on every objective.
Source: DIR Security Control Standards Catalog v2.1
What is the Texas Cybersecurity Framework?
TCF is the official cybersecurity framework owned by the Texas Department of Information Resources (DIR). It is mandatory for state agencies (per SB 820), public universities, junior colleges, and nonprofits accepting state funding. The Texas Education Agency operationalizes TCF for K-12 through the K-12 Cybersecurity Initiative.
42 Control Objectives
Comprehensive coverage across the legacy NIST CSF 5-function model: 11 Identify, 24 Protect, 4 Detect, 2 Respond, 1 Recover.
6-Point Maturity Scale
DIR's 0-5 scale is derived from CMMI and ISO/IEC 21827 (SSE-CMM). Districts target Level 3 (Well Defined) to align with DIR / TEA expectations.
DIR-Backed
Backed by the DIR Security Control Standards Catalog (v2.1), which is itself derived from NIST SP 800-53 Rev. 5. TCF assessments are DIR-aligned by construction.
5 Core Functions, 42 Objectives
TCF uses the legacy NIST CSF 5-function model. Each objective is independently scored on a 0-5 maturity scale.
Identify
Privacy, data classification, asset inventory, policy framework, risk management, compliance, cloud security, third-party providers.
Protect
Awareness training, cryptography, configuration management, contingency planning, access control, identification, perimeter, content filtering, spam, DLP.
Detect
Vulnerability assessment, malware protection, security monitoring and event analysis, audit logging and accountability.
Respond
Cyber-security incident response and privacy incident response, including coordination with DIR, TEA, ESCs, and statutory notification timelines.
Recover
Disaster recovery procedures, including backups, restoration, alternate processing, and continuity for SIS / financial / identity systems.
Total Objectives
Each objective scored independently. The assessment surfaces gaps relative to DIR's 3.0 target so districts know exactly where to invest first.
The DIR 0-5 Maturity Scale
Each objective is rated 0 to 5. The DIR-recommended target for state agencies and the K-12 convention TEA aligns to is Level 3 (Well Defined).
Not Performed
The control objective is not addressed by the organization in any meaningful way.
Performed Informally
Ad hoc, undocumented. Outcomes are inconsistent and depend on individual effort.
Planned
Planned and tracked. Procedures may exist but are not consistently followed across the organization.
Well Defined DIR Target
Documented, standardized, and consistently performed across the organization. The DIR-recommended target for state agencies and the K-12 alignment.
Quantitatively Controlled
Measured with quantitative metrics; performance is predictable and deviations are managed statistically.
Continuously Improving
Continuously optimized through innovation, automation, and root-cause analysis. Performance improvements are sustained.
How the Assessment Works
Walk through all 42 objectives. Score your current maturity. See the gap to target and where to invest first.
Set Your Scope
Identify your organization (K-12 ISD, state agency, university, nonprofit). The assessment uses K-12 target maturity by default; state-agency mode uses DIR's strict 3.0 across all objectives.
Score Each Objective
Walk through 11 Identify, 24 Protect, 4 Detect, 2 Respond, and 1 Recover objective. Click 0-5 to record current maturity. Each objective ships with a level-by-level rubric.
Review Gaps
See the function-by-function breakdown and a sortable list of every objective with its gap from target. Top-10 gaps are highlighted.
Generate Reports
(Phase b โ coming) Export a formatted TCF assessment report, a UCPA-prioritized remediation roadmap, and a multi-framework view (TCF โ NIST CSF 2.0 โ CIS Controls).
Time Estimate
A complete TCF self-assessment typically takes 2-3 hours with the rubric in front of you. Districts that have done a CIS Controls or NIST CSF assessment recently can usually finish in under 90 minutes.
What to Have Ready
- Board-adopted security policy / acceptable use policy (TASB CQB)
- Asset inventory (SIS, financial, identity systems first)
- Incident response plan; vendor / third-party register
- Status of TEA-funded controls (EDR, MFA staff email, DMARC, local admin restriction)
Sample Assessment View
Score each objective on the 0-5 maturity scale
What You'll Receive
Generate reports that meet DIR methodology and translate directly to other frameworks your district may already be measured against.
TCF Assessment Report
Function-by-function maturity scoring against all 42 TCF objectives, formatted to align with DIR's expected structure. Districts can submit this to TEA / DIR or use it internally for board reporting.
- Radar chart across 5 functions
- All 42 objectives with current vs. target
- DIR-aligned executive summary
UCPA Remediation Roadmap
FrameworkMapper's Universal Control Prioritization Algorithm ranks every gap by impact ร maturity-delta โ surfacing the objectives that move the needle the most for a typical Texas K-12 environment.
- Ordered by impact ร gap, not flat priority
- TEA-funded control alignment flags
- Tooling suggestions where inventory is known
Multi-Framework View
The same evidence rendered against NIST CSF 2.0, NIST 800-53 Rev. 5, and CIS Controls v8.1. A district doing a TCF assessment effectively gets a partial CSF and CIS readout for free.
- TCF โ NIST 800-53 Rev. 5 (~95% coverage)
- TCF โ NIST CSF 2.0 (~90% coverage)
- TCF โ CIS Controls v8.1 (~75% coverage)
K-12 Specifics
Each objective is tagged for its FERPA, HB 18 (Texas Education Code ยง32.1021), and TEA initiative intersections. The K-12 view filters out objectives that don't apply to district scope.
- FERPA + HB 18 statutory crosswalk
- TEA-funded control alignment per objective
- ESC partnership-friendly export
Beyond Compliance
See Your Results Through an Attacker's Eyes
Completing your assessment unlocks FrameworkMapper's threat-informed views โ the same control scores, re-read against real adversary behavior from MITRE ATT&CK® and curated threat intelligence.
Threat Lens & Adversary Likelihood
Advanced reports that map your control scores to attacker techniques and rank which adversaries are most likely to succeed against you.
Threat-Informed Executive Report
A board-ready PDF with your Attack Surface Coverage Score (ASCS) and kill-chain exposure, computed from your actual answers.
Incident Response Packet
Your assessment answers and evidence pre-fill a Responder Brief and evidence bundle, so responders can act on day one. Learn more
Included With Your Subscription
Runs on the FrameworkMapper Bundle
This assessment is part of the FrameworkMapper Bundle โ one per-framework subscription that also includes Gap Optimization, the Threat-Gap Visualizer, the Incident Response Packet, and progress check-ins with phone photo evidence capture, across a 12-month term.
How Pricing WorksReady to Assess Your TCF Posture?
Start your TCF self-assessment today. Score 42 objectives, see the gap to target, and build a TEA-aligned roadmap.
Contact sales at sales@frameworkmapper.com
Where the Data Comes From
Some content on this assessment is verbatim from DIR; other content is FrameworkMapper-derived interpretive material. We label both clearly so districts, ESCs, and DIR reviewers know exactly what they are looking at.
Authoritative (from DIR)
- Objective definitions — verbatim from the DIR TCF Controls and Definitions document, May 2025 revision.
- Maturity scale level names and definitions (0–5) — from DIR's framework, derived from CMMI and ISO/IEC 21827 (SSE-CMM).
- State agency target = 3.0 on every objective — DIR Security Control Standards Catalog v2.1 convention.
FrameworkMapper interpretive content
- K-12 target maturities (a mix of 2.0 / 2.5 / 3.0 across the 42 objectives) are FrameworkMapper-recommended interim targets, reflecting realistic Texas ISD capacity given current TEA initiative scope. They are not a DIR or TEA published per-objective target. Districts wanting the strict DIR 3.0 baseline can switch the assessment to "State agency target."
- Per-objective level-by-level rubric text — for 38 of 42 objectives the rubric language is template-generated. For 4 objectives (Access Control, Spam Filtering / DMARC, Malware Protection, Disaster Recovery) the level 3 description is hand-authored with K-12 specifics referencing TEA-funded controls. DIR's published TCF document does not include per-objective level-by-level rubrics.
- UCPA priority scores and crosswalks to other frameworks — computed and authored by FrameworkMapper.
Full provenance for every field lives under the provenance block in the canonical
tcf_v2025-05.json dataset.
Sources & Attribution
- Texas Department of Information Resources. Texas Cybersecurity Framework (TCF) Controls and Definitions, May 2025 revision. dir.texas.gov
- Texas Department of Information Resources. DIR Security Control Standards Catalog v2.1, June 2023.
- Texas Education Agency. K-12 Cybersecurity Initiative. tea.texas.gov